Security Requirements Driven Risk Assessment for Critical Infrastructure Information Systems

Seok-Won Lee, Robin A. Gandhi, Gail‐Joon Ahn · 2005

Major information processing and associated value-added services provided by information systems in critical infrastructures are being increasingly used for various purposes irrespective of their security posture. Although several infrastructure-wide standard security Certification and Accreditation (C&A) processes exist, their effectiveness in the real world is challenged by the complexity of information systems and their diverse socio-technical operational environments. We identify that these factors naturally demand the integration of several modeling techniques, to adequately support the breath and depth of C&A processes, with complementary semantics and levels of abstraction to elicit, represent and analyze the diversity of factors associated with the system under consideration. Furthermore, to promote cohesiveness between the artifacts captured through this approach, we identify the need for a comprehensive framework that allows them to synergistically understand and link to each other through the application domain concepts, properties and their relationships. In this paper, we specifically focus on the interactions between various models within such a framework based on the relationships between security requirements and the elements of risk assessment for driving an objective, repeatable and justifiable risk assessment process.

Read the paper · More papers on PaperTik